Add password authentication
This commit is contained in:
+64
-15
@@ -1,5 +1,10 @@
|
||||
const http = require('http');
|
||||
const net = require('net');
|
||||
const {
|
||||
checkPassword,
|
||||
createSession,
|
||||
isValidSession,
|
||||
} = require('./auth');
|
||||
|
||||
const port = 8080;
|
||||
const fulcrumTimeoutMs = 3000;
|
||||
@@ -222,36 +227,80 @@ async function getStatus() {
|
||||
}
|
||||
|
||||
const server = http.createServer(async (req, res) => {
|
||||
if (req.method === 'POST' && req.url === '/api/login') {
|
||||
let body = ''
|
||||
|
||||
req.on('data', (chunk) => {
|
||||
body += chunk
|
||||
})
|
||||
|
||||
req.on('end', () => {
|
||||
try {
|
||||
const input = JSON.parse(body)
|
||||
|
||||
if (!checkPassword(input.password)) {
|
||||
res.writeHead(401, {
|
||||
'Content-Type': 'application/json',
|
||||
})
|
||||
res.end(JSON.stringify({ error: 'Invalid password' }))
|
||||
return
|
||||
}
|
||||
|
||||
const token = createSession()
|
||||
|
||||
res.writeHead(200, {
|
||||
'Content-Type': 'application/json',
|
||||
'Set-Cookie': 'munin_session=' + encodeURIComponent(token) +
|
||||
'; HttpOnly; Secure; SameSite=Strict; Path=/; Max-Age=86400',
|
||||
})
|
||||
res.end(JSON.stringify({ ok: true }))
|
||||
} catch {
|
||||
res.writeHead(400, {
|
||||
'Content-Type': 'application/json',
|
||||
})
|
||||
res.end(JSON.stringify({ error: 'Invalid request' }))
|
||||
}
|
||||
})
|
||||
|
||||
return
|
||||
}
|
||||
|
||||
if (req.url === '/api/status') {
|
||||
if (!isValidSession(req)) {
|
||||
res.writeHead(401, {
|
||||
'Content-Type': 'application/json',
|
||||
})
|
||||
res.end(JSON.stringify({ error: 'Authentication required' }))
|
||||
return
|
||||
}
|
||||
|
||||
try {
|
||||
const status = await getStatus();
|
||||
const status = await getStatus()
|
||||
|
||||
res.writeHead(200, {
|
||||
'Content-Type': 'application/json',
|
||||
});
|
||||
})
|
||||
|
||||
res.end(JSON.stringify(status));
|
||||
res.end(JSON.stringify(status))
|
||||
} catch (error) {
|
||||
console.error('Failed to get service status:', error);
|
||||
console.error('Failed to get service status:', error)
|
||||
|
||||
res.writeHead(500, {
|
||||
'Content-Type': 'application/json',
|
||||
});
|
||||
})
|
||||
|
||||
res.end(
|
||||
JSON.stringify({
|
||||
service: 'running',
|
||||
error: 'Failed to determine service status',
|
||||
}),
|
||||
);
|
||||
res.end(JSON.stringify({
|
||||
service: 'running',
|
||||
error: 'Failed to determine service status',
|
||||
}))
|
||||
}
|
||||
|
||||
return;
|
||||
return
|
||||
}
|
||||
|
||||
res.writeHead(404);
|
||||
res.end('Not found');
|
||||
});
|
||||
res.writeHead(404)
|
||||
res.end('Not found')
|
||||
})
|
||||
|
||||
server.listen(port, () => {
|
||||
console.log(`Status API listening on port ${port}`);
|
||||
|
||||
Reference in New Issue
Block a user